Intune licensing depends on who uses a device and how it is managed. Compare user and device licensing for personal devices, shared terminals and kiosks before choosing a plan.

Device-only license is intended for supported device scenarios without binding to a specific user. It does not automatically replace a user license for all features. Microsoft lists limitations for app protection policies, Conditional Access, and other user features in Intune licensing overview.

First, describe what is being managed

For the device, write down who logs in, whether they have their own work profile and what applications they use. Then describe the security requirement. "We want devices in Intune" is an insufficient goal.

A kiosk that displays a single operating application is different from a shared laptop on which ten people open their mail and documents in turn. In both cases, the hardware is shared, but the user services are different.

Separate device ownership and licensing model when making decisions. Corporate ownership does not mean device-only. And a private phone doesn't have to be out of protection just because the company doesn't want to take over its full management.

Decision table

Overview of scenarios and controls
ScenarioThe main questionAssessment direction
Personal business laptopDoes the employee need their own apps and policies?User authorization and supported registration
Kiosk without user profileIs this a supported enrollment method?Device-only may be appropriate
Shared computer with personal mailWhat rights do logged in people need?Assess equipment and user services separately
Personal phone with working OutlookIs it enough to protect work data in the application?MAM and user permissions
Meeting techniqueWhat specific type of device and service does it use?Do not confuse Intune with a Teams Rooms license
Administrative accountIs it only for administration, or also for work use?Admin access does not cover normal use of services

The table shows the reasoning process. Select the final product based on target features, supported platform and enrollment.

Device-only has its own limits

Microsoft supports specific device registrations without binding to users. Therefore, before purchasing, confirm how the device will be registered. Additionally, changing a pilot created in user mode can be more difficult than preparing a proper start.

Also rate apps. An Intune license covers management; it does not automatically grant rights to the Office desktop, enterprise application, or paid service running on the device.

If a user logs in on a device-only device, do not infer entitlement to user features from a successful login. Review each requirement separately, especially application protection and conditional access.

MDM and MAM address a different layer

MDM manages the device. MAM protects work data in supported applications. For private mobiles, the second approach may be more appropriate when a business needs to manage work with corporate mail and files, but does not need to take over the entire phone.

Microsoft states that app protection policies can be used without MDM enrollment. However, you must verify the supported applications, platform, and user license.

Use specific situations when explaining to employees: what the company can manage, what work data can be deleted, and what remains personal. A general announcement "the phone is under IT control" unnecessarily creates confusion.

Conditional Access is another component

Intune can provide device or app status while Entra makes access decisions. One does not replace the other. Therefore, keep the entire chain in the budget and during the test.

The device may be enrolled, but the user may still not meet the policy requirement. Conversely, successful device management does not yet prove that a sensitive application cannot be opened from another client. Also check the forbidden paths.

For applications on mobile platforms, Microsoft describes app protection and Conditional Access collaboration. Select the specific control according to the currently supported design, not according to the old screenshot.

Female employee using a mobile phone on the corporate terrace

Model example: store and private phones

A hypothetical store has four shared terminals and twelve employees. The terminals serve the cash register application. At the same time, employees want work mail on their own mobile phones.

The administrator does not order only four device-only licenses and does not consider the whole scenario resolved. First, it assesses terminal management. It will separately evaluate people's mail permissions, mobile app protection and access policies.

The result can be a combination of different products. However, it needs a clear link to services and users. The exact number of licenses is derived from the confirmed model, not the number of screens itself.

How to prepare a pilot

  1. Select a representative device and a typical user.
  2. Confirm license model and supported enrollment.
  3. Deploy the necessary applications and configuration.
  4. Test the first login and repeated work.
  5. Check the compliance status and any access policies.
  6. Try transferring data between work and personal applications.
  7. Verify logout, transfer and deletion of work data.

For a shared device, repeat the pilot when switching between two people. For BYOD, include a personal account in the same application. It is these situations that can reveal the difference between expectations and actual behavior.

How to diagnose a broken policy

Start with your identity and registration method. Determine whether you expect a user- or device-targeted policy. Then check the audience membership, application support and processing status.

Do not use changing the primary user as a one-size-fits-all fix. It may help in a specific model, but it does not solve the missing claim or inappropriate enrollment.

For the incident, record the device, user, policy, time, and specific expectations. "Intune doesn't work" is much more difficult to solve than "this phone can copy an attachment from work Outlook to a personal application".

What to record in the long term

Maintain purpose, owner, platform, enrollment, and licensing model for devices. For the user, his permissions and work needs. Add confirmation of who approved the exception.

Repeat the check when changing use. A kiosk converted to a regular work computer may need a different model. Likewise, a shared laptop given to one employee.

Frequently asked questions

Is device-only enough for all people on a shared computer?

Not automatically. Assess each user's supported device features and services.

Do I need Intune if I don't register a private phone?

If you use Intune app protection, verify appropriate user permissions even without MDM enrollment.

Is administrative access without a license a right to use Intune services?

No. Administration of the portal and use of services are assessed separately.

Will Intune solve the licensing of office applications?

No. Administration and distribution of the application do not grant the right to use it.

The best basis for an order

Prepare a list of scenarios, not just a list of devices. For each, list the user, application, enrollment, and desired protection. The partner can then confirm the exact model without guessing what the company means by "shared".